I used brakeman for generating scanning reports in my application. It generated many Cross Site Scripting security warnings with High Confidence in my reports/show page:
Unescaped model attribute near line 104: Report.find(params[:id]).remarks
I have seen in the link but couldn't fix. Please help. And this is the line in show page which I am facing error:
<%= @report.remarks.html_safe %>